The billion engineers building sandbox tools at the moment are missing the point. Sandboxing doesn't matter when the LLM is vulnerable to prompt injection. Every MCP server you install, every webpage it fetches, every file it reads is a threat. Yeah you can sit there and manually approve every action it takes, but then how is any of this useful when you have to supervise it constantly? Even Anthropic say that this do…
Building secure, scalable agent sandbox infrastructure
11–19 of 19 posts
Re: Building secure, scalable agent sandbox infrastructure
#12The first 3 “hardening” points are not great. Essentially it’s just: remove .py files an execute del os.environ[“SESSION_TOKEN“]? This doesn’t really sound very secure, there are a number of ways to bypass both of these. It’s just security through obscurity
The actual security model is the architecture itself: the sandbox runs in its own VM inside a private VPC. It has no AWS keys, no database credentials, no LLM API tokens. The only thing it can do is talk to the control plane, which validates every request and scopes every operation to that one session.
So even if you bypass all three hardening steps, you get a session token that only works inside that VPC, talking to a control plane that only lets you do things scoped to your own session. There's nothing to escalate to.
The bytecode removal, privilege drop, and env stripping are just there to make the agent's life harder if it tries to inspect its own runtime. Not the security boundary.
Re: Building secure, scalable agent sandbox infrastructure
#13I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?
We haven't open-sourced the control plane glue yet but it's something we're thinking about. browser-use itself is open source. The sandbox infra on top is the proprietary part for now.
Re: Building secure, scalable agent sandbox infrastructure
#14The missing layer is pre-installation scanning. Runtime isolation + supply chain vetting together is the real answer.
Re: Building secure, scalable agent sandbox infrastructure
#15The billion engineers building sandbox tools at the moment are missing the point. Sandboxing doesn't matter when the LLM is vulnerable to prompt injection. Every MCP server you install, every webpage it fetches, every file it reads is a threat. Yeah you can sit there and manually approve every action it takes, but then how is any of this useful when you have to supervise it constantly? Even Anthropic say that this do…
Yup. I just wrote about this last week: https://tachyon.so/blog/sandboxes-wont-save-you Of all the problems in agent security, sandboxing solves the easiest problem.
Re: Building secure, scalable agent sandbox infrastructure
#16Re: Building secure, scalable agent sandbox infrastructure
#17I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?
Re: Building secure, scalable agent sandbox infrastructure
#18I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?
Agreed, the pattern is converging across the industry. The Unikraft setup is where it gets interesting for us with sub-second boots (or sub 100ms even), scale-to-zero that suspends the VM after a few seconds of idle (frees resources), and dedicated bare metal in AWS so we're not sharing hardware. We haven't open-sourced the control plane glue yet but it's something we're thinking about. browser-use itself is open sou…
Re: Building secure, scalable agent sandbox infrastructure
#19I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?